2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-57714CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoin...
CVE-2026-57710CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Usi...
CVE-2026-57707CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl...
CVE-2026-57702CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture ...
CVE-2026-57401CRITICAL9.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDas...
CVE-2026-41041CRITICAL9.1URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache...
CVE-2026-22103CRITICAL9.3The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22102CRITICAL9.3A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce...
CVE-2026-22098CRITICAL9.2Various sensitive information such as passwords and charging card UIDs are written to log files.
CVE-2026-22097CRITICAL9.3The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the...
CVE-2026-22096CRITICAL9.3The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a...
CVE-2026-22095CRITICAL9.3The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22093CRITICAL9.5The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b...
CVE-2026-13014CRITICAL9.2A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute...
CVE-2026-14453CRITICAL9.6This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l...
CVE-2026-57830CRITICAL9.1Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten...
CVE-2026-4769CRITICAL9.8Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu...
CVE-2026-11964CRITICAL9.1The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-p...
CVE-2026-15511CRITICAL9.8A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function sy...
CVE-2026-10666CRITICAL9.8parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the...
CVE-2026-61876CRITICAL9.4LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ...
CVE-2026-56271CRITICAL9.8Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr...
CVE-2026-56260CRITICAL9.1Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf end...
CVE-2026-61447CRITICAL10PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-...
CVE-2026-61445CRITICAL9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now